Coldcard Firmware Weakness Exposed in Third Suspected Attack Wave
A third suspected wave of attacks on Bitcoin addresses generated by vulnerable Coldcard firmware has drained an estimated $88.6 million from the cryptocurrency, according to Galaxy Research.
The total amount stolen now stands at approximately 1,367 BTC, with 4,585 affected addresses across three waves.
The third wave used a different transaction pattern than the first two, which followed a funnel structure and used pay-to-witness-public-key-hash destinations. The new wave used pay-to-witness-script-hash destinations and batched an average of 6.37 victim addresses into each transaction.
Coldcard has been affected by a weakness in its random-number library, introduced in March 2021, which limited the securely distinguished output streams to no more than 2^32 under fixed fallback conditions.